HireFT
Browse JobsHow it worksPricingAboutSuccess Stories
    Back to jobs
    IN

    Inplno

    [Industry]

    Security Analyst

    Arlington, United StatesOn-SiteFull-time1–3 yrs experiencePosted 1w ago
    All Inplno jobs

    Job description

    **This position requires Secret Security Clearance**

    COMPANY OVERVIEW

    Founded in 2008, LNO, Inc. is a rapidly growing SBA certified Service-Disabled Veteran-Owned Small Business (SDVOSB) and Native American-Owned business headquartered in Augusta, Georgia. We are a proven team of highly experienced former service members, Instructors, System Engineers, Network Administrators, Cybersecurity Experts, Electronics Technicians, Field Service Engineers, Systems Designers, Logisticians, and Project Management professionals. Our core capabilities include delivering leading-edge  solutions to the most common technology challenges we are asked to solve such as Systems Integration, Equipment Configuration and Validation, Network Modernization, Cybersecurity Operations, Mission Operations, and Technology and Business Training.

    • Senior Security Analyst

      LNO is seeking an Information Cloud Security Analyst to support The Department of State. This is a unique and challenging opportunity in the Office of the Chief Technology Officer (CTO) in Diplomatic Security, US Department of State. CTO is the primary IT group within the Bureau of Diplomatic Security, providing many web applications and other services used by Federal and local law enforcement officers worldwide.

      Location:

      · Arlington, VA (on-site required)

      Clearance:

      • Minimum Secret Clearance
      • Preferred Top Secret Clearance

      Responsibilities:

      • Design, implement, and maintain robust cloud security controls within Microsoft Azure using Microsoft Defender for Cloud and Azure Policy to ensure continuous compliance and threat protection.
      • Establish secure artifact collection pipelines using Azure Artifacts and Azure Container Registry (ACR). Enforce strict vulnerability scanning, provenance tracking, and immutable build controls on all software packages and container images.
      • Proficiency with Azure Pipelines or GitHub Actions to build "security gates" that automatically fail vulnerable build.
      • Perform analysis to ensure security controls are consistently implemented throughout system development life cycle and continuous monitoring phase.
      • Partner directly with Developers to help them remediate code vulnerabilities and coordinate with Cloud Architects to ensure that automated security guardrails align with broader infrastructure designs.
      • Develop, document, and execute plans for monitoring, assessing, and verifying security controls across assigned information systems
      • Documenting security control implementation statements.
      • Work with cross functional teams across the bureau to complete all RMF steps with a focus on 1-3.
      • Request, gather, and comprehend evidence required to closeout open POAMS.
      • Execution and knowledge of FISMA tasks that consist of system authorization/reauthorization, Privacy Impact Assessments, and system security categorization required for DS application systems.
      • Optimize processes to meet IT security-related goals and strategies by documenting lessons learned for each system and application by authorization month and year.
      • Enter test results and artifacts into the bureau/department repository
      • Document assessment activities and results in sufficient detail to enable external review of all assessment processes, activities, results, and conclusions
      • Support bureau review of assessment activities, reports, and conclusions
      • Develop and maintain all required Assessment documentation following NIST 800-53 requirement for Steps 1, 2, 3, 4 (remediation of independent assessment findings), 5 (Provide artifacts for Authorization Official Approval/Review Package), 6 (Continuous Monitoring actions) of the Risk Management Framework for all Bureau managed systems
      • Provide security expertise to ensure security controls are implemented and the resulting documentation and artifacts are current
      • Provide guidance to key stakeholders on the necessary components to demonstrate the achievement of control objectives
      • Implement a NIST-compliant continuous monitoring process across all major information systems to provide periodic assurance to senior management on the security protections of major information systems; and
      • Support periodic assessment of a bureau-identified subset of security controls across assigned information systems.
      • All other duties assigned

      Qualifications:

      Preferred

      • Microsoft Certified: Azure Security Engineer Associate (AZ-500) or Azure Fundamentals (AZ-900).
      • Prior Azure cloud security, DevSecOps (scanning code as security), and secure artifact management experience.
      • Experience working in a matrix organizational structure.
      • Previous experience using Archangel, GRC, JIRA, and/or Service Now
      • Some knowledge of SDLC, project manage principles, and ITIL.
      • Knowledge of the FAM and FAH Policies

      Required:

      · B.A and/or B.S.

      • 1–3 years of experience in IT security, DevOps, or system administration with a foundational understanding of Microsoft Azure.
      • Basic understanding of CI/CD concepts using Azure Pipelines or GitHub Actions.
      • Knowledge of NIST Rev 4 and 5 security controls.
      • Expert in the processes and documentation requirements for RMF methodologies
      • Advanced practical experience in managing all phases of systems A&A activities ranging from early concept development to system retirement.
      • Demonstrated experience supporting Government Agencies preferably DOS.
      • Proficient or able to gain proficiency with a broad array of security software application and tools
      • Organized with attention to detail
      • Willing to learn

    Job details are sourced from the employer's original posting.

    Open job posting
    IN

    About the company

    Inplno

    INPLNO is a company that operates in the [Industry] sector.

    View all Inplno jobsinpl.eu
    Industry
    [Industry]
    Open roles
    6

    Interested in this role?

    Apply with HireFT

    Free to start — no card required.

    Your fit

    How well do you match?

    Sign in to see how your résumé lines up with this role.